CVE-2026-97484
CVE CVE-2026-97484EUVD EUVD-2026-86082Published 2026-09-24T16:04:27.000ZLast changed 2026-09-28T05:30:15.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: usbip: vhci_hcd: fix NULL deref in status_show_vhci platform_get_drvdata() can return NULL if a VHCI host controller's probe failed (e.g. due to USB bus number exhaustion). status_show_vhci() checked for a NULL pdev but not for a NULL hcd returned by platform_get_drvdata(). Passing NULL to hcd_to_vhci_hcd() does not return NULL - it returns a pointer offset of 0x260, causing a NULL pointer dereference when that value is subsequently dereferenced. Add a NULL check on hcd before calling hcd_to_vhci_hcd(). Move status_show_not_ready() above status_show_vhci() to make it callable from the new error path without a forward declaration.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 0775a9cbc694e8c7276688be3bbd2f386167ab54 <dacd7c317ba12e035653c28a0eaaf23d91abc073; patch: 0; patch: 6.18.53; patch: 6.12.111; 0775a9cbc694e8c7276688be3bbd2f386167ab54 <046a94fdb02eb1df86c8fa4614104ff801ba3ab7; patch: 7.2; 4.9; 0775a9cbc694e8c7276688be3bbd2f386167ab54 <bc150783542ba2e7c1257d1299c6f3269bdba270
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.